The ransomware note landed at 2:14 on a Saturday morning. By the time anyone at the company read it — Sunday afternoon — the intruders had been inside for eleven days, the backups were encrypted along with everything else, and no one could find the phone number for the cyber-insurance hotline. The breach itself took minutes. The chaos that followed lasted three weeks.
I've been pulled into enough of these to spot the pattern early. The wound that cripples a small or mid-sized business is rarely a missing firewall. It's the missing plan for the first six hours — the stretch where panic, not policy, tends to make the decisions.
The first six hours decide the rest
There's a comfortable myth that incident response is enterprise theatre: something you need only once you have a 24/7 SOC and a compliance department. That's backwards. Large organizations survive messy incidents because they carry redundancy and keep lawyers on retainer. An SME survives on speed and clarity, and both evaporate the moment nobody knows who is allowed to pull a server offline.
Consider the clock you don't control. Many regulators — and most cyber-insurance policies — expect notification within 72 hours of discovery. Miss it and you're not just breached; you're exposed to fines and a voided claim. When teams "figure it out" live, they burn the first day arguing about who has authority while the attacker quietly exfiltrates a second database.
What actually belongs in the playbook
A good playbook is not a 60-page binder nobody opens. It's a short, specific set of answers to questions you won't want to think about mid-crisis:
- Who decides. One named incident lead, with a named backup. Not a committee. This person can authorize disconnecting systems, engaging outside help, and — if needed — pausing operations.
- Who to call, offline. Phone numbers for your IT lead, legal counsel, insurer, and a forensics firm — printed, not stored only in the email system the attacker may now own.
- Severity, defined in advance. A simple three-tier scale, so a laptop with malware and a live data breach don't trigger the same 3 a.m. all-hands.
- Pre-authorized containment. The specific actions your team may take without waiting for sign-off — isolating a host, resetting credentials, blocking an account.
- Communication templates. Draft language for staff, customers, and regulators, written calmly today so you're not composing it under legal pressure at midnight.
- Evidence, preserved. A one-line rule: don't wipe and reimage the compromised machine before someone captures the logs. You cannot investigate what you've already deleted.
Run the drill before the real thing
A plan you've never rehearsed is a hypothesis. The single highest-return exercise I recommend costs nothing but ninety minutes and a meeting room: a tabletop drill. Read out a scenario — "finance reports an odd wire transfer; a workstation is behaving strangely" — and walk the team through it, decision by decision, out loud.
The first tabletop always exposes the same thing: everyone assumed someone else had the backups, the contacts, or the authority. Far better to discover that in a conference room than at 2 a.m.
Run it twice a year. Rotate the scenario. Time how long it takes to reach the "we are containing this" moment — that number is your real security posture, far more than any tool on your network.
Where to start Monday
You don't need budget or a consultant to begin. Open a single page. Write down three things: who your incident lead is, the five phone numbers you'd need at 2 a.m., and the three actions your team is pre-authorized to take on their own. That one page already puts you ahead of most SMEs I meet.
From there, schedule the first tabletop and let it show you the gaps. Readiness isn't a document you finish — it's a habit you keep.
The question worth putting to your team this week isn't "are we secure?" It's "when it happens, do we know the first three moves?"